Because they are sloppy.
They leak IPs all the time otherwise. CF should work for them, but they seem incapable of getting things set up say properly.
Hiding the sites seems like a good idea, but proper policies and checksums clearly aren't in place. Never have been.
First time you fail like...